Files
claude/plugins.lock.json
T
Bastien Chanot b4896c9ae1 job6: gsd-pi 2.64.0→3.0.0 — adapt status-reporter parser to ADR-013 cutover
Upgrade confirmed format-incompatible before use (job6 gate, BATCH-2):
gsd-pi 3.0.0 no longer writes .gsd/ROADMAP.md (verified by generating a
real test milestone in a scratch project) — state moved to .gsd/STATE.md,
.gsd/gsd.db (authoritative DB), and one .gsd/milestones/<ID>/<ID>-ROADMAP.md
per milestone, all in a different markdown shape. Every grep/awk in
status-reporter.md PHASE 3 would silently print 0/blank against the old
path instead of erroring.

Rewired PHASE 3 to read `gsd headless query` (stable JSON snapshot, no LLM
call) instead of scraping markdown — smoke-tested against both the absent
case (this repo, no .gsd/) and a real gsd-managed scratch project.

plugins.lock.json pin bumped deliberately to 3.0.0 (update-all.sh honors
the pin; this is the required manual bump).
2026-07-07 03:23:19 +02:00

47 lines
3.0 KiB
JSON

{
"_readme": "Pinned versions for reproducible installs. Update versions deliberately, then run install-plugins.sh.",
"rtk": {
"source": "https://github.com/rtk-ai/rtk",
"version": "latest",
"note": "Check latest at https://github.com/rtk-ai/rtk/releases before updating"
},
"gsd": {
"source": "npm:gsd-pi",
"version": "3.0.0",
"note": "Check latest at https://www.npmjs.com/package/gsd-pi before updating. GSD is a standalone CLI (Pi SDK), not a Claude Code plugin. Run 'gsd' in terminal, not '/gsd' in Claude Code. ADR-013 cutover (3.0.0): DB is authoritative, .gsd/ROADMAP.md no longer exists — read state via 'gsd headless query' (see agents/status-reporter.md PHASE 3), not markdown scraping. NOTE: update-all.sh honors this pin — 'make update' will NOT advance gsd past it; bump this version deliberately, then re-run."
},
"gstack": {
"source": "https://github.com/garrytan/gstack.git",
"managed_by": "git submodule",
"note": "Version controlled by submodule pointer in .gitmodules. Update: git submodule update --remote"
},
"ctx7": {
"source": "npm:ctx7",
"version": "latest",
"note": "Context7 CLI — doc lookup for fast-evolving libs. Standalone CLI, not an MCP server. Install: npm install -g ctx7. Standalone: ctx7 docs /vercel/next.js \"middleware\"."
},
"graphifyy": {
"source": "pypi:graphifyy",
"version": "latest",
"managed_by": "pipx",
"note": "Codebase knowledge graph. CLI is 'graphify'. Install: pipx install graphifyy && graphify install && graphify claude install. Adds PreToolUse hook for Glob/Grep."
},
"semgrep": {
"source": "pypi:semgrep",
"version": "1.168.0",
"managed_by": "pipx",
"note": "SAST engine for the security gate (security-auditor agent, onboard cso fallback, audit-delta). Rulesets pinned in-agent: p/security-audit + p/secrets (never --config auto). BLOCKING gate -> pin honored by update-all.sh: 'make update' will NOT advance semgrep past it; bump deliberately (new rules = new BLOCKs on unchanged code). Never run 'semgrep login' automatically (Pro rules are optional, guide-only)."
},
"emil-design-eng": {
"source": "https://github.com/emilkowalski/skill",
"path": "skills/emil-design-eng/SKILL.md",
"managed_by": "curl",
"note": "Emil Kowalski's design engineering skill — UI polish, animations, component craft. Downloaded to skills-external/emil-design-eng/, symlinked by link.sh."
},
"impeccable": {
"source": "npm:impeccable",
"version": "3.2.0",
"note": "Design anti-pattern detector (45 deterministic rules, CLI 'impeccable detect', exit 0/2) + /impeccable skill (23 verbs) by pbakaus. Pin = CLI version; the skill dist has its own release track fetched by 'skills install'. Pinned for audit reproducibility (LRN-077 class: a rules update silently changes audit output). Requires Node >= 24 — install step skips gracefully below that. Machine-owned: synced to skills-external/impeccable/ (gitignored), symlinked by link.sh."
}
}